CVE Database
/

CVE-2021-23842

Back to search

CVE-2021-23842

Published: Jan 19, 2022

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.1

5.7

MEDIUM

Description

Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the key from the firmware to decrypt network traffic between the AMC2 and the host system. Thus, an attacker can exploit this vulnerability to decrypt and modify network traffic, decrypt and further investigate the device\'s firmware file, and change the device configuration. The attacker needs to have access to the local network, typically even the same subnet.

VendorProductVersions

Bosch

AMS

affected
unspecified - < 4.0

Bosch

APE

affected
unspecified - <= 3.8.x

Bosch

BIS

affected
unspecified - < 4.9.1

Bosch

AMC2

affected
all

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Attack Vector

Adjacent

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now